Vulnerability, Potential Exploit In Cisco WLAN APs
An anonymous reader writes "The AirMagnet Intrusion Research Team has uncovered a new wireless vulnerability and potential exploit associated with Cisco wireless LAN infrastructure. The vulnerability involves Cisco's Over-the-Air-Provisioning (OTAP) feature found in its wireless access points. The potential exploit, dubbed SkyJack by AirMagnet, creates a situation whereby control of a Cisco AP can be obtained, whether intentionally or unintentionally, to gain access to a customer's wireless LAN."
exploit, unintentionally?
a situation whereby control of a Cisco AP can be obtained, whether intentionally or unintentionally, to gain access to a customer's wireless LAN.
Unintentionally?
It's one thing to accept that in the perpetual arms race you'll regularly fall behind and your job is to limit those situations to a manageable minimum. It's a completely differnt matter when a non threatening actor may stumble upon a vulnerability.
"Yes, sir, the bank doors do open automatically when a stray cat passes in front of it at night. You see, cats have precisely the size we didn't account for in our supersecure doors."
How do you unintentionally gain access to something? How should I picture this? "Gee, officer, I was leaning against this door and then it suddenly opened and I tripped and then I must have stumbled into the jewelry box and all those rings just happened to pour into my pockets, dunno how this happened..."
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Apparently you can 'just' disable Over-the-Air-Provisioning (OTAP) to remove the threat, so it's not that big of a deal I'd say.
.... Is a wire from the computer to the network.
This is my opinion. To make sure you don't steal it, it's covered by the DMCA.
If you actually read the article, you will realize this is a non-issue. Basically, if you install a new, non provisioned access point, it is vulnerable to being assigned to a fake controller. This won't give access to your network. It will give them control of a rogue AP, but that's about it. There is nothign here you couldn't do if you stuck an AP of your own somewhere nearby. The article gives no method for taking control of an existing provision access point, or gaining access to any data on the network. You can get some ip's of the Cisco controller, but if it's already on the wireless segment of your LAN that's not exactly top secret information. This "attack" is obvious from the very principle of how OTAP works. You plug in an AP, it finds the nearest Cisco controller, and pulls the necessary config. Anyone could see that's not secure. It's a feature designed for convenience in low security networks (aka the majority of wifi installations). Personally, I would never have trusted it to actually work reliably in the first place, and just configured the ap's before installing them.
The articles real motive is clear in the last paragraph:
Customers should also leverage a dedicated independent IDS system, like AirMagnet Enterprise â" capable of detecting wireless snooping with hacking tools to alert staff to the potential of an impending exploit. Furthermore, networking professionals should use such a monitoring system to validate that all corporate APs detected over the air are actually represented at the WLAN controller â" as any corporate AP that is not associated to a controller could be a serious security risk.
AKA buy their shit. Surprise surprise, a company that makes a tool to detect exploits in AP's found a "security vulnerability" that their program can help with.
OTAP and UPNP from the beginning on any Linksys/Cisco hardware. Personally I see absolutely no reason even in a Home network to enable either of those features for just this possible reason. Sure it's a bit more effort to configure things using a wired connection. The main advantage is I don't have to worry about a badly implemented version of UPNP (lots of apps include it) that can screw MY internet connection up. Hell I don't even want the potential for someone to even use UPNP to configure my router so they can dl Porn or other garbage.
Mod me up/Mod me down: I wont frown as I've no crown